    ossec-hids-2.8.1-48.suse12.3.art                                                              $   >                                  Yi4[RmTOÛ   >                 >  NP   ?     N@      d                                                	   #        	   X          8          <          X          \          q          u        	                                                       :          :  	     `   :  
        :          :       V   :          :       x   :          :                 (   :                 `                    H     (     {     )          *          +          ,          -          8        l  9        l  :     '   l  =     B     D     B      G     B(   :  H     C   :  I     C   :  X     D4     Y     DD     \     D   :  ]     Ep   :  ^     H     b     I     d     J     e     J#     f     J(     l     J*     u     J<   :  v     K$   	  w     L   :  x     L   :  y     M   C ossec-hids 2.8.1 48.suse12.3.art An Open Source Host-based Intrusion Detection System OSSEC is a scalable, multi-platform, open source Host-based Intrusion Detection
System (HIDS). It has a powerful correlation and analysis engine, integrating
log analysis, file integrity checking, Windows registry monitoring, centralized
policy enforcement, rootkit detection, real-time alerting and active response.
It runs on most operating systems, including Linux, OpenBSD, FreeBSD, MacOS,
Solaris and Windows.

This package contains common files required for all packages.   Uwleatherback.atomicorp.com    <http://www.ossec.net GPL Atomicorp <support@atomicorp.com> Applications/System http://www.ossec.net/ linux i386 if ! id -g ossec > /dev/null 2>&1; then
  groupadd -r ossec
fi
if ! id -u ossec > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossec
fi
if ! id -u ossecr > /dev/null 2>&1; then
  useradd -g ossec -G ossec       \
	-d /var/ossec \
	-r -s /sbin/nologin ossecr
fi             !  |  8  `               d           c      
?     	        }            P       '             8  A            O    	       {                  A큤AhAhAhhhhhhhhhhhAhhhhhhhhhhhhhAhAhAA聠AAhAAAhA                                                                                                                    UwUwT_UwT_T_T_T_T_UwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwUwbcd6e512c9627c6d09a2e852db43a1aa  dd96f5ec41c601c09f99252272c38aac 9e7417e6440f786de46b42cd31eee384 f18762365fcf687764a89f4126dd7a9d b4318998d4d34431f536824bee4dc766 3a3fca440e5142141f75613396dc55be 0d7fd090a120b378bd44a18319085d88 620bb7958e0665fa9dd3a544ae944a15    25887bdd240bc502c80c970a926132bc ac2254ffe808f2e1e6a2059f7b6b70d6 6696d5e6b1464d63569507419a7b3582 b18f166b9aa7abfbd0500b75c6ace41d 851774e0589294606efd31266ae922ce 91819d33fc1831c33090e6f12634c446 4cbab6aeb963b00fec11fb2c4367ff51 54265163fd59969371516ae7cf4024ee 8038838ce614839b69607b0c8d3dcd95 2eb0f40856189205d103e3116389cf54  8de9f76b53e3d931ca91b5b30e93e30d 3837e5b595795be4a4b7ab8a686419fc 151469d3db7b9984f283b3db84bd4805 c4686eb10052796a091cc2631cc26066 37bedae6ed6bb5f7b4a81b05d111110c 01998b783ae3e744910ca5fa48284e15 607f15a31477667a929b39fe93fd0ef3 5153a546ff0b249f5e5fad7336864753 3029b1c8b4452e9220e1dd0d5e3d1146 e970334d6ed40cec19ed160e0edd9503 afd8198e717c69712a39abf88d737bfd f96dec8e2bbbbba81547d8a8ca5f1f4e  0a925a9273f76d0c11923f81b3a3f166    8bbb43059e784bc7897d8afa91db4420 87a3dacc9168f4bcb24de133d93f3d25 8b01dd3679f38c62cd275c72cdf5f88d 4fb4e5adb8b146c8c1661b026c4ccec3 c305bfe360442ace1a893b033da10aba bc0ae4fa2bc3aa0359da50cfc5dc60ae 1ab23dcbf166a3d52088d6880adac31b 137905d4645eb4a91764e1fde96bdbcd 10b8dc27d937b26821fda7f91e2e281f 821a6d25c7871410bc13a1c995cfbb13 2db61ae3efd9250fe63cdac8579d005f bb55cdd41f77ea7a53c5f7b50fc2dbc7                                                                                                                                                                                                                                                                                                 root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec root root root root root root root root root root root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec root ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec ossec-hids-2.8.1-48.suse12.3.art.src.rpm   config(ossec-hids) ossec-2.8.1-48.suse12.3.art ossec-hids ossec-hids(x86-32)            @   @               
  
  
/bin/sh /bin/sh /bin/sh /usr/bin/env /usr/sbin/groupadd /usr/sbin/useradd config(ossec-hids) inotify-tools rpmlib(CompressedFileNames) rpmlib(PayloadFilesHavePrefix) rpmlib(PayloadIsLzma)       2.8.1-48.suse12.3.art  3.0.4-1 4.0-1 4.4.6-1 4.10.2 [ -r /etc/localtime ] && cp -fpL /etc/localtime /var/ossec/etc glibc         Uv@TT@SSS[S@R@R@RʚR@R@RrF@RiRR@Q@QY@Q@@QQ@Q@Qu&@Qu&@QkQg@Q\PDPP@PP@OiO@OЗOЗO	O OpZ@NNS@NK@N;@N;@N6@N-ZNMMM@M@M@M?MM>MUM@MPL~L8LΫLΫLʷ@LeL@L{LL@LA@LLLzL~@@L|LvW@LmLa?@LRL4l@LT@KtK͗@KKK@K[K@K8@K@K@K@J@JJJ@JJJn@JL@JI@J2C@J2C@J/@J&eI@Io@I)@I4IܑISupport <support@atomicorp.com> - 2.8.1-48 Support <support@atomicorp.com> - 2.8.1-47 Support <support@atomicorp.com> - 2.8.0-46 Support <support@atomicorp.com> - 2.8.0-45.1 Support <support@atomicorp.com> - 2.8.0-45 Support <support@atomicorp.com> - 2.7.1-44 Support <support@atomicorp.com> - 2.7.1-43 Support <support@atomicorp.com> - 2.7.1-42 Support <support@atomicorp.com> - 2.7.1-41 Support <support@atomicorp.com> - 2.7.1-40 Support <support@atomicorp.com> - 2.7.1-36 Support <support@atomicorp.com> - 2.7.1-35 Support <support@atomicorp.com> - 2.7-34 Support <support@atomicorp.com> - 2.7-33 Support <support@atomicorp.com> - 2.7-32 Support <support@atomicorp.com> - 2.7-31 Support <support@atomicorp.com> - 2.7-30 Support <support@atomicorp.com> - 2.7-29 Support <support@atomicorp.com> - 2.7-28 Support <support@atomicorp.com> - 2.7-27 Support <support@atomicorp.com> - 2.7-26 Support <support@atomicorp.com> - 2.7-25 Support <support@atomicorp.com> - 2.7-24 Support <support@atomicorp.com> - 2.7-23 Support <support@atomicorp.com> - 2.7-22 Support <support@atomicorp.com> - 2.7-21 Support <support@atomicorp.com> - 2.7-20 Support <support@atomicorp.com> - 2.7-19 Support <support@atomicorp.com> - 2.7-17 Support <support@atomicorp.com> - 2.6-16 Support <support@atomicorp.com> - 2.6-15 Support <support@atomicorp.com> - 2.6-14 Support <support@atomicorp.com> - 2.6-13 Support <support@atomicorp.com> - 2.6-12 Support <support@atomicorp.com> - 2.6-11 Support <support@atomicorp.com> - 2.6-10 Support <support@atomicorp.com> - 2.6-9 Support <support@atomicorp.com> - 2.6-8 Support <support@atomicorp.com> - 2.6-7 Support <support@atomicorp.com> - 2.6-6 Support <support@atomicorp.com> - 2.6-5 Support <support@atomicorp.com> - 2.6-4 Support <support@atomicorp.com> - 2.6-3 Support <support@atomicorp.com> - 2.6-2 Support <support@atomicorp.com> - 2.6-1 Support <support@atomicorp.com> - 2.6.0-0.10 Support <support@atomicorp.com> - 2.6.0-0.9 Support <support@atomicorp.com> - 2.6.0-0.8 Support <support@atomicorp.com> - 2.6.0-0.7 Support <support@atomicorp.com> - 2.6.0-0.6 Support <support@atomicorp.com> - 2.6.0-0.5 Support <support@atomicorp.com> - 2.6.0-0.4 Support <support@atomicorp.com> - 2.6.0-0.3 Support <support@atomicorp.com> - 2.6.0-0.1 Support <support@atomicorp.com> - 2.5.1-10 Support <support@atomicorp.com> - 2.5.1-9 Support <support@atomicorp.com> - 2.5.1-8 Support <support@atomicorp.com> - 2.5.1-7 Support <support@atomicorp.com> - 2.5.1-6 Support <support@atomicorp.com> - 2.5.1-5 Support <support@atomicorp.com> - 2.5.1-4 Support <support@atomicorp.com> - 2.5.1-3 Support <support@atomicorp.com> - 2.5.1-2 Support <support@atomicorp.com> - 2.5.1-1 Support <support@atomicorp.com> - 2.5-1 Support <support@atomicorp.com> - 2.5-0.9 Support <support@atomicorp.com> - 2.5-0.8 Support <support@atomicorp.com> - 2.5-0.7 Support <support@atomicorp.com> - 2.5-0.6 Support <support@atomicorp.com> - 2.5-0.1 Support <support@atomicorp.com> - 2.4.1-11.2 Support <support@atomicorp.com> - 2.4.1-11.1 Support <support@atomicorp.com> - 2.4.1-10 Support <support@atomicorp.com> - 2.4.1-9 Support <support@atomicorp.com> - 2.4.1-8 Support <support@atomicorp.com> - 2.4.1-7 Support <support@atomicorp.com> - 2.4.1-6 Support <support@atomicorp.com> - 2.4.1-5 Support <support@atomicorp.com> - 2.4.1-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.2 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.4-0.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.3-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta2.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.2.0.beta1.1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-3 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.1-1 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-11 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-10 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-9 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-8 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-7 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-6 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-5 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-4 Scott R. Shinn <scott@atomicrocketturtle.com> - 2.0-2 - Security fix for CVE-2015-XXXX - Update to 2.8.1. This is identical to 2.8.0-46, the only change is the hosts.deny CVE-2014-5284 is merged in. - Revert BR#1596
- Add Bugfix for hosts.deny race condition (CVE-2014-5284) - BR #1596, Add fork limiting patch (max 10) for execd to prevent DoS conditions - Upgrade to 2.8.0 - Feature Request #1512,  speed up shuns in execd, move sqlite down - Relink against native mysql - Add ar-tracking active response - Placeholder for null exclusion rules.  Legacy support - ASL 4 version with new database format - Add support for Fedora 20
- Modify optimization flags for FORTIFY - Update to 2.7.1
- Add independent rules.d/decoders.d ossec-rules package - FR#772, add rule 3360 for postfix slow brute force
-   add dovecot-decoder.patch for cpanel dovecot
-   Update 9702, 9753 for dovecot brute force
- FR#773, add rule 11308 for pure-ftp slow brute force
- FR#1347, Update for courier v4 decoder (pop3s)
- FR#1359, Update horde decoder for v5 - Disable ossec-dbd signature table (replaced by aslw_rules). This was very slow - Break ossec-dbd into separate package
- FR#1321, update courier-imap decoder for version 4.0 - Bugfix #XXX, prevent truncating last character on ossec-dbd database inserts on the alerts/data table - Add tld column to alert table w/ index - Deprecate internal id generation in dbd
- update schema to autoincrement, increase id space to int - Add is_hidden to mysql schema - Add if exists to mysql schema - Add os_dbd-mysql-replace-query.patch to consolidate SELECT/UPDATE into REPLACE sql - Consolidate alert & data into a common table
- Add ossec-authd init script - Add sqldelete command  to execd
- Update to clear sqlite db at startup - More minor updates to GeoIP tracking - Minor update to GeoIP tracking - Bugfix on permissions for files in shared/ directory for client installs
- Add GeoIP support
- Remove dependency on perl-DBD-SQLite
- Update asl-shun to new non-perl based version.
- Deprecate firewall-drop-update.patch
- Add sqlite support to execd (/var/ossec/var/execd.sqlite) - Update to 2.7 final - Feature Request #XXX, revert duplicate detection in log events to help detect extremely fast brute force attacks
- Add FORTIFY_SOURCE, PIE, and relro (full) - Update to 2.7-rc2 - Update to 2.7-rc1 - Move active response components under the common package - bugfix #xxx, correct ownership permissions on fts dir - Update to init script to suppress spurious execd output
- Add alerts queue to server package with ossec/ossec permissions - Bugfix #XXX, correct any/agentd condition - Moved agentless packages under server - Drop timeid and cat_id indexes from schema - Add new index, timeid to alerts table. - Add cmoraes patch, Adds config options for enabling/disabling rootkit/syscheck options, and agent config profiles
- Add ossec-memleaks patch
- Add agentless directories, and agent.conf
- Bugfix #XXX, ossec-hids.init will now return an exit code on status - Add prelink_cmd support - Bugfix #XXX, display multi-line events in data table correcty - Update to asl-shun.pl purge event to default to 24 hours. - Update to asl-shun.pl to change ordering of block rules
- Revert from 0805 snapshot - Update to 0805 snapshot - Update to 0801 snapshot
- Update asl-shun.pl to log to active-responses.log, blocks now go to the named chain ASL-ACTIVE-RESPONSE, and delete events are more redundant. - Update to OSSEC 2.6 Final - Update to snapshot 110711 - Update to snapshot 110613 - Update to snapshot 110609 - Update to snapshot 110606
- Moved ossecr user creation event to the ossec-hids core package - Update to snapshot 110531 - Update to snapshot 110526 - Update to snapshot 110504 - Bugfix #536, Increase the default sleep time for syscheck - Renamed to 2.6 branch - Add support for the rules/decoders dir system - Update to snapsot 110405
- Update asl-shun to support ossec alert ids - Changed asl-shun sqlite database to /var/ossec/var/blocklist3.sqlite
- asl-shun database format now stores the full alertid - Update to snapshot 101203 - Update to snapshot 101125 - Added alertid support to os_dbd, this involves a schema update - Added dst ip, src prt, and dst prt capture support to os_dbd - Bugfix #XXX, manage_agents was built in client mode for the server package. - Add clamav decoder & ruleset - Update to 2.5.1 final - Update to 2.5 final - Update to 0928 snapshot - Extended no_ar into ossec-dbd - Add no_ar option to disable active response per rule - Update to snapshot 100920 - Update snapshot to 100907 - Snapshot 100901 - Added test fix for os_dbd - Bugfix #376, ossec-control will now properly stop and reload - Update to 0809 snapshot - Relink against native mysql - Add minicon decoder from les fenison - Update to 100707 snapshot
- Feature Request #371, add ossec.log to logrotate - Updated to 100615 snapshot - Updated init and ossec-server scripts to support the new reload feature. - Update to 2.4.1 - Added zabbix reporting active response - Update to 2.4 final
- Lowered courier rule 3910 (failures) from 6 over 240 to 10 over 10
- Lowered courier rule 3911 (success) from 10 over 60 to 30 over 20 - Rebuilt for atomic repo - Update to CVS 100317 - Update to CVS 100311
- Add decoder for denyhosts
- Update asl_rules.xml to include denyhosts rules - Update to CVS 100309 - Added new decoder for smtp_auth
- Added rules to detect smtp_auth brute force attempts
- Added rules to detect imap/pop brute force attempts - Updated ossec-server.conf to be in parity with the ASL config
- Added templates dir for generating configs - Update to 2.3 release - Update to snapshot 091109 - Update to snapshot 091008 - Update to snapshot 090925
- Added timestamp field to the mysql schema
- Bugfix #XXX, for the ossec-client.init script to call the correct (renamed) ossec syscheckd/logcollector daemons
- Appologies for not updating the previous changelogs. Missed a few updates! - Update to snapshot 090827
- Feature Request #225, Added logrotate event to active-response log
- Updated system_audit_rcl.txt to look for the correct php.ini file - Update to 090824, beta 1 release - Update to 090812 snapshot - Rebuild agent daemons with -DCLIENT, added symlink trickery - update to 2.1.1 - update to 090630 snapshot, this has fixes for CentOS/RHEL 4 64-bit environments - update to 2.1 final - update to snapshot 090612 - update to snapshot 090610 - update to snapshot 090603 - Disable postgresql support, to get around an undesirable dependency on EL4 - Update to snapshot 090417 - Update to snapshot 090413 (this adds in inotify support) - Update to snapshot 090410 (this adds in inotify support) - Update to snapshot 090408 - Added authpsa rules back in, this is used to detect brute force attacks
- Added conditional building support for ASL modifications /bin/sh /bin/sh                                                                                                                                                                                                          	   
                                                                      !   "   #   $   %   &   '   (   )   *   +   ,   -   .   /   0   1   2   3   4   5   6   7   8   9   :                                                                        2.8.1-48.suse12.3.art  2.8.1-48.suse12.3.art 2.8.1-48.suse12.3.art                                                                                                                        	   	   
   
   
   
   
   
   
   
   
   
   
   
                  ossec-hids ossec-hids BUGS CHANGELOG CONFIG CONTRIBUTORS INSTALL LICENSE README.md ossec active-response bin ar-tracking.sh asl-shun.pl disable-account.sh firewall-drop.sh host-deny.sh ip-customblock.sh ossec-tweeter.sh restart-ossec.sh route-null.sh zabbix-alert.sh agentless main.exp register_host.sh ssh.exp ssh_asa-fwsmconfig_diff ssh_foundry_diff ssh_generic_diff ssh_integrity_check_bsd ssh_integrity_check_linux ssh_nopass.exp ssh_pixconfig_diff sshlogin.exp su.exp bin ossec-configure etc shared templates active-response.template apache-logs.template ar-disable-account.template ar-firewall-drop.template ar-host-deny.template ar-routenull.template pgsql-logs.template rootcheck.template rules.template snort-logs.template syscheck.template syslog-logs.template logs queue diff ossec var run /etc/logrotate.d/ /usr/share/doc/packages/ /usr/share/doc/packages/ossec-hids/ /var/ /var/ossec/ /var/ossec/active-response/ /var/ossec/active-response/bin/ /var/ossec/agentless/ /var/ossec/bin/ /var/ossec/etc/ /var/ossec/etc/templates/ /var/ossec/queue/ /var/ossec/var/ -O2 -g -m32 -march=i486 -fmessage-length=0 -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables drpm lzma 5 i386-suse-linux                                                                                                                                                                                  ASCII text POSIX shell script, ASCII text executable Pascal source, ASCII text UTF-8 Unicode text UTF-8 Unicode text, with very long lines a /usr/bin/env expect script, ASCII text executable directory exported SGML document, ASCII text                                                                                   	       
                                                                                                                                                                                                                                                                                                                                             R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R  R     ?       ]    "k%M{Usg`Y{
 e8\pdȷ;,8jIr	e+ j6Cg/OJGI[t[|dsFcES'ց­*__a?wW
	~ZG#x*F:y$Uڲ9L;)fB
gEv|Q$#E8ǫL,+\5g͛+ӗ=
XłjtWRq=LIuE4jr.!vz*[\lqĸp4%_@Ny{x脾cpgDp.:Bfc
ɤ\}ڪ=,̄I:-.5ʑO!bzQYAQ[:NxMnaXB~V6h

` jҎ=22<V8QV7ɉVpeux!["YEM-CH^dk{-#!Yo$a9}x݇ @XN0Xxgk:-Xsr쇓#27 $r\.OToT0eEzkli`&zCiIyP9QϦ-2.aY*TIt$~DǠ|@\kύZк2><DT!]~Βs/jFMaLX^v5b< jelPZ#3kvh-p(#G
쭂{φ1GBB^I+W!Wv	oߵyN@@m8@S$љh~oĢYQd-?(U5tYn8P	=?zgJ>|UҌNV9)CX[>>a'h%Td}71H;3FRr>xo١=ڭJQ8h6\y}e"#|#ies;]+_lKpK|lr%^bC֟\9y{+dVvo1V~V|,)<`5*[anZyEU3)9U4L
c=nJ]4a[y2f*2D
0	I}*xV`%*OQz 5byc2|ꮣelVZN5vO (,M.CV9>t`]sy5,Y\T;^f
|5|p=s`4Sߍciz>ݎXjTgXUR%׶O$3K}	tI'/-(  `uE/cA5ԠyhlƺX-aǈFcHT-%ѫ[:MΗ齗B'Y*̟sk.vhW4۟pychyl&C/b2\(̫:zH1#YouXuvrƅ0ӂ&L??.>,ƃQdg19v1ކ@^`"s΄8qLPn-OESPރ14з~+vk=Qq04{w[E{Ovo/TIHGĬՉ&1\ùSygfwc@U1+O"P^3®oiA{q%b :q5$n%Uck?U?D٫s"Db x6n